A 19-year-old alleged member of the Scattered Spider hacking group, Peter Stokes, has been extradited from Finland to the United States to face charges of conspiracy, computer intrusion, and fraud. Stokes, a dual U.S. and Estonian citizen, appeared in a Chicago federal court on June 30, 2026, where a judge ordered him held in custody. He was arrested in April 2026 by Finnish police on an Interpol Red Notice and extradited in late June.
Court records identify Stokes by the online handle ‘Bouquet’ and describe at least four intrusions, the first when he was 16. In May 2025, prosecutors allege he and others broke into a luxury jewelry retailer, copied its data, and demanded approximately $8 million in cryptocurrency. The retailer refused to pay and spent at least $2 million on remediation. Finnish officers seized two 2-terabyte hard drives when they stopped Stokes at Helsinki airport as he attempted to board a flight to Japan.
Scattered Spider, also tracked as Octo Tempest, UNC3944, and 0ktapus, is a loose, English-speaking group of young individuals spread across the U.S., U.K., and Europe. The group specializes in social engineering attacks, particularly targeting IT help desks to reset passwords or approve logins. They are best known for the 2023 attacks on MGM Resorts and Caesars Entertainment, and have been linked to breaches at U.K. retailers, U.S. insurers, and airlines. Assistant Attorney General A. Tysen Duva stated the group has been involved in over 100 network intrusions, resulting in more than $100 million in ransom payments.
Stokes is part of a broader crackdown on Scattered Spider members, including Tyler Buchanan, who pleaded guilty in April 2026; Noah Urban, sentenced to 10 years in August 2025; and Thalha Jubair and Owen Flowers, who pleaded guilty in June 2026 for attacks on Transport for London and U.S. health systems. Mandiant reported a lull in attacks after the 2025 arrests but warned that other groups are copying Scattered Spider’s tactics. Defenses focus on stricter identity checks for help desk resets and phishing-resistant sign-in keys.
CVEs: CVE-2026-20245
Attack groups: Scattered Spider, Octo Tempest, UNC3944, 0ktapus
Companies: MGM Resorts, Caesars Entertainment, Marks & Spencer, Harrods, Co-op, Twilio, LastPass, Transport for London, SSM Health, Sutter Health, Mandiant
Original source: thehackernews.com